Friendly fraud
A cardholder disputing a charge they genuinely made, keeping both the goods and the refund. Sometimes deliberate, sometimes a household member who does not recognise the entry, and from the merchant's side the two are indistinguishable at the moment of the claim.
Why it matters to you
This is the fraud your fraud tooling is worst at, because the transaction was legitimate by every signal it checks. The device was right, the address was right, the card was present. Defence is evidential rather than preventive: delivery proof, session records and a dispute process that can produce them quickly.
Where we meet it
It is taught, not just committed. Walkthroughs circulate explaining which wording a given issuer accepts and how long to wait, which is what turns an individual excuse into a repeatable technique.
Connected terms
Refunder
A specialist who obtains refunds for goods that were delivered and kept, by exploiting a retailer's returns process rather than its payment systems. Sold as a service, priced as a share of the order value, with different operators known for different merchants.
Carding
The trade in stolen payment card data and the craft of turning it into goods: testing cards, choosing merchants, shipping to reshippers. An economy with its own schools, slang and reputations.
Drop
A money or goods mule: the recruited (sometimes unwitting) person whose bank account or address launders the proceeds. Recruited openly, in "work" channels, at scale.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.